Our Support
for Your Business
Our Support Options
A healthy deployment. Protection under continuous care.
We keep your WanGuard deployment technically healthy and help adapt it to changing load. In SILVER your team runs the protection configuration. From GOLD we also review the configuration regularly and implement agreed corrections, to reduce the risk of an ineffective response and of unnecessary blocking.
| Support tasks | SILVEREntry | GOLDSystem care | GOLD +Weekends & holidays | PLATINUMFull handover |
|---|---|---|---|---|
| Support availability | Business daysMon–Fri | Business daysMon–Fri | 7 days a weekweekends and holidays too | 7 days a weekweekends and holidays too |
| Response to a request | Next business day | Same business day | Same day | Same day |
| Help with WanGuard and Linux operation, plus updates We answer questions about operating and running the deployment. We carry out updates twice a year and critical (CVE) updates, with changes agreed beforehand. We remind you of important dates, including the end of the WanGuard licence and of technical support. | ✓ | ✓ | ✓ | ✓ |
| Threshold recommendations, backups and help with false positives We help choose detection settings and identify the causes of unwanted alarms. We maintain system backups. In SILVER, applying recommendations to the protection configuration stays with your team; from GOLD we carry out the agreed corrections. | ✓ | ✓ | ✓ | ✓ |
| Process monitoring and automatic recovery of sensors and filters We monitor the state of WanGuard processes. In the cases covered by the mechanisms in place, sensors and filters are restored automatically. Problems that require an engineer are handled within the package you choose. | ✓ | ✓ | ✓ | ✓ |
| Deployment supervision and tuning, more than 400 parameters We monitor more than 400 parameters of the deployment components: CPU, memory, disks, network cards, databases, BGP, DPDK and Flow and SNMP sensors, depending on the configuration. We react to problems we find and tune resources and databases to the load. This helps keep the deployment healthy also when the number of anomalies grows during attacks. | ✓ | ✓ | ✓ | ✓ |
| Event analysis and detection tuning We analyse recorded anomalies and attacks together with how the protection rules behaved, and prepare corrections that improve detection and reduce false positives. In GOLD and GOLD+ the day-to-day watching of alarms stays with your team; the scope of incident handling is set out in the offer. | ✕ | ✓ | ✓ | ✓ |
| Technical consultations and configuration review In Zoom sessions we go through anomalies, detection thresholds, planned changes and questions from your administrators. We agree how protection should behave, taking into account the role of each subnet and service. | ✕ | ✓ | ✓ | ✓ |
| ITORO implements the agreed protection changes We prepare and implement agreed thresholds, list assignments and WanGuard response settings, once you approve them, and we check the effect. Your administrator receives a summary of the work done instead of translating a multi-page audit into console settings. | ✕ | ✓ | ✓ | ✓ |
| We find gaps and errors in the protection configuration Our program checks the whole configuration under audit: prefixes defined in WanGuard, list assignments, required decoders, units and threshold values, and response settings. We point out which corrections to make first and carry them out as part of the agreed work. Once the deployment is prepared, reviews run every two weeks. We also check the effect of the changes. | ✕ | ✓ | ✓ | ✓ |
| Traffic profiling tailored to your network We use traffic history stored in ClickHouse and the profiling capabilities of WanGuard 9.0. ITORO configures and tunes profiles for IP addresses and subnets, taking account of their purpose and normal traffic patterns. We define acceptable deviations, minimum trigger levels and the response: notification or activation of protection. These profiles complement threshold lists and help detect events that may remain below fixed thresholds. We introduce changes in stages and check their impact on legitimate traffic. | ✕ | ✓ | ✓ | ✓ |
| We show the board the scale of threats and the state of protection We present the number and scale of confirmed attacks, the periods of highest activity and an assessment of how protection performed, based on the data available. The board gets an understandable summary of the situation in the network. The cadence of these summaries is agreed with you. | ✕ | ✓ | ✓ | ✓ |
| We point out the threats an administrator should deal with first We passively analyse available external data on open services, vulnerable versions and reported threats, and combine it with WanGuard events. Your administrator receives ordered recommendations with an urgency rating, in particular for hosts that show both vulnerability signals and attack activity. Changes outside WanGuard stay with you unless agreed otherwise. | ✕ | ✓ | ✓ | ✓ |
| We take over WanGuard administration We administer the deployment and watch alarms day to day, within the agreed scope and service hours. You tell us about changes in the network and service needs, and ITORO prepares and carries out the agreed work. Your team does not have to operate the WanGuard console day to day. | ✕ | ✕ | ✕ | ✓ |
| Scope of care | 4 of 12 items | 11 of 12 items | 11 of 12 items | 12 of 12 items |
| Pricing |
€350 /month
annually in advance €3,850 12 months for the price of 11 |
€1,500 /month
annually in advance €16,500 12 months for the price of 11 |
€1,800 /month
annually in advance €19,800 12 months for the price of 11 |
€4,000 /month
annually in advance €44,000 12 months for the price of 11 |
The choice comes down to how much of the day-to-day work stays with your team and how much ITORO takes over.
Under attack? 24/7 rapid response
When an attack is live, minutes matter. Our emergency package gives you a direct line to ITORO engineers and a defined escalation path, day or night.
- 24/7 contact for active DDoS incidents
- Protection online in as little as 2 hours when your server & router are prepared (RTBH / BGP FlowSpec)
- Hands-on tuning of WanGuard, FlowSpec and RTBH during the attack
- Priority handling for GOLD / PLATINUM customers
Reports when you need them
We don't flood you with paperwork after every event. When an incident must be reported to a regulator or government agency, ITORO prepares the documentation on request, with the exact scope, depth and format agreed in advance with sales so it meets your country's and agency's requirements.
- Attack timeline: start, peak, vectors and duration
- Traffic evidence and volumetric graphs (pps / bps)
- What was mitigated, how, and the impact avoided
- Regulatory summaries (e.g. NIS2) tuned to your jurisdiction, provided under the emergency package
- Recommendations to harden against the next attack
DDoS resilience is now a legal obligation
NIS2 makes DDoS protection and incident reporting mandatory for ISPs, telecoms and digital infrastructure across the EU. Here is what the directive asks for, and how ITORO covers it.
Technical & organizational measures
Operators must take appropriate, proportionate measures to manage risks to their networks, including protection against availability attacks such as DDoS.
How ITORO covers it: WanGuard detection paired with Juniper MX line-rate filtering, BGP FlowSpec and RTBH: tuned to your network so attacks are stopped, not just observed.
Incident reporting
Significant incidents must be reported to the national CSIRT within 24 hours (early warning), 72 hours (assessment) and one month (final report).
How ITORO covers it: We prepare the attack timelines, traffic evidence and post-incident reports you need to meet those deadlines: see the reports section below.
Management accountability
Senior management is directly accountable for cybersecurity risk management and can be held liable for non-compliance.
How ITORO covers it: Documented, tested DDoS protection and a clear 24/7 escalation path give management defensible evidence of due diligence.
Broad scope & real penalties
NIS2 covers ISPs, telecoms, cloud, data centers and digital infrastructure. Fines reach up to €10M or 2% of global annual turnover.
How ITORO covers it: ITORO gets you compliant on the resilience side before it is tested, as an Andrisoft Gold Partner with network practice going back to 2005.